Skip to content

ESET uncovers EmissarySoldier: LuckyMouse APT group compromised government networks and private companies (telco, media and banks) in Central Asia and the Middle East

The research featured in ESET’s industry report on government works in concert with perspectives from the European Commission, CERN and Europol presented at the ESET European Cybersecurity Day virtual conference on April 28.

BRATISLAVA – The European Union’s cybersecurity strategy, and that of all governments globally, has been challenged not only in its move to “digital by default,” but also by the COVID-19 pandemic, the mass movement to working from home, and threats such as cyberespionage, ransomware and supply-chain attacks. Above all, the most formidable challenge, and foe, shared by all governments is advanced persistent threat (APT) groups.

APT groups leveraging evolved tools
The ESET industry report on government examines the threatscape APT actors are erecting, and underlines its complex nature with an exclusive look at EmissarySoldier, a malicious campaign brought to bear by the LuckyMouse APT group using its SysUpdate toolkit to compromise machines, some of which were running the popular application Microsoft SharePoint.

This dive into LuckyMouse examines its relatively unknown SysUpdate toolkit – the first samples of which were discovered in 2018. Since then, the toolkit has seen various development stages. LuckyMouse’s current modus operandi is to install its implants via a so-called trident model that uses three components: a legitimate application vulnerable to DLL hijacking, a custom DLL that loads the payload and a raw Shikata Ga Nai-encoded binary payload.

Overview of the trident model

Since SysUpdate’s modular architecture enables its operators to limit exposure of malicious artifacts at will, ESET researchers did not retrieve any malicious modules and expect this to be an ongoing challenge in future analyses. Regardless, LuckyMouse increased its activity in 2020, seemingly going through a retooling process where various features were being incrementally integrated into SysUpdate’s toolset.

The evolution of tools leveraged by APT groups like LuckyMouse is of key concern as governments are vested with the responsibility to ensure stability for citizens, the business environment and engagement with other nation-states. These tasks of governance are under threat as LuckyMouse and other APT groups, including state actors and their collaborators, home in on widespread collaboration platforms like Microsoft SharePoint and digital by default service provision.

Government in focus
The years 2020 and 2021 have seen several ESET research collaborations come to maturity, including engagements with the likes of the European Organization for Nuclear Research (CERN, Europol, and the French National Cybersecurity Agency (ANSSI). Many of their perspectives, shared at the virtual event and in the report, stress that governments and their IT infrastructure exist as default targets.

The report highlights the need for technologists to continue supporting governments in closing security gaps and monitoring the tactics, techniques and procedures of APT groups via the various endpoint detection and response technologies at their disposal. To download the report, visit WeLiveSecurity.com and make sure to follow ESET Research on Twitter.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

無線實物攝影機如何提升教學互動的5種方法

IPEVO VZ-X是一款無線實物攝影機,改變及創新上課教學的方式。VZ-X具有Wi-Fi、HDMI和USB等三種連接模式,可以投影即時影像至電腦、iOS / Android 設備,或直接與投影機或電視一起使用。

現在,讓我們來看看無線實物攝影機如何提升教學互動的5種方法。

  1. 小型教室授課提升互動性

在小型教室授課,想展示每位學生的作品給全班看時,只需要一台 VZ-X 無線實物攝影機和大螢幕便可輕鬆達到這個目的。可以手持 VZ-X 在教室間走動,輕鬆拍攝學生作品、展示投影到大螢幕上。 因為使用 Wi-Fi 傳輸影像,行動無需受線材限制,電池續航時間更長達12小時,讓課堂或會議進行時不受干擾,提高成效並享受豐富的互動過程 。

  1. 大型教室或會議環境亦適用

在大型教室、會議空間或場地時,VZ-X也很適合。透過Wi-Fi模式,講者將設備連線至VZ-X便可以自由移動,不必擔心線材的限制。講者亦可在大型講堂裡,輕鬆展示作品在更大的銀幕上,供所有人觀看。

  1. 線上學習

使用VZ-X作為網路攝影機,透過第三方通訊軟體(例如teams、skype、line和Zoom)可以進行視訊會議、遠距教學或線上學習。經由Wi-Fi將VZ-X連接到設備,不受線材的限制,並且能持續保持網路連線。

在VZ-X Wi-Fi模式下需要保持網路連線時,可參閱詳細的步驟指南.

  1. VZ-X無線連接至iPad,搭配IPEVO WHITEBOARD白板軟體,可在影像上筆記、註解

使用VZ-X搭配 IPEVO WHITEBOARD App,擴展「無線」自由,授課、學習或簡報的呈現如虎添翼。這是一款可應用在簡報時,製作及分享筆記註釋、圖片、實物、文字和螢幕的軟體。

只需將VZ-X透過Wi-Fi連接到iPad並開啟 IPEVO WHITEBOARD,便能開始筆記、註釋。不僅如此,還可以錄製聲音、影像以及使用截圖功能。亦可分享至大螢幕上,讓更多觀眾觀看,當然是以無線方式,讓簡報方式更自由。

豐富的功能及工具,讓IPEVO WHITEBOARD PRO成為相當受歡迎的軟體,這些功能包含20 個背景範本、消失墨水、瀏覽視窗、新增地圖、子母畫面、雷射筆等。

  1. VZ-X搭配 IPEVO Visualizer軟體使用

IPEVO Visualizer 可提供使用者展示、錄製和編輯來自電腦攝影鏡頭的影像。電腦開啟IPEVO Visualizer並與VZ-X配對後,新的視覺化方式可讓簡報、展示更生動。例如使用閱讀輔助工具、分割螢幕、子母畫面、慢動作錄影等以及許多其他功能,增進課堂趣味。

使用閱讀輔助功能時,另有附加工具,如線條標記、螢光條、放大鏡及遮罩模式等。分割螢幕功能在簡報時可使用兩個攝影鏡頭,同時並排展示不同的文件或實物進行比較。

子母畫面是Visualizer另一個有趣的功能,影片錄製或現場直播時,使用主窗口來展示呈現,而子窗口則可以觀看講者生動解說。慢動作錄影功能則是讓使用者錄製慢動作影片,呈現不同效果。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於IPEVO
IPEVO源自於PChome Online硬體事業部門,2007年7月正式獨立。自2004年於台灣營運Skype網絡電信服務,使台灣成為Skype全球發展中最成功的市場。2005年起以IPEVO品牌推出一系列Skype專屬硬件產品,將Skype虛擬服務轉化為使用者實質經驗。IPEVO以簡單、實際且具有價值的經驗為產品目標,其簡潔俐落的產品風格呼應著IPEVO的核心思考與產品精神。目前已研發之產品包括:Skype有線USB話機、Skype無線話機、Skype會議系統、Skype視訊設備、Stand-alone免電腦Skype話機。

How are businesses of different sizes using FinTech solutions?

For the purposes of this blog, we have categorized small businesses as comprised of 2-49 people, medium as comprised of 50-499 and large as comprised of 500+.

Small and medium-sized enterprises (SMEs) have long been underserved by traditional financial providers. Yet, over the past few years, we have seen new FinTech offerings come to the marketplace designed specifically for small-scale operations. FinTech is no longer a choice restricted to the big corporations. We have seen innovative ways to make payments, manage money and get financing for businesses of all sizes.

Indeed, FinTech companies are broadening their offerings by designing solutions for small businesses. In return, small businesses are actively investing in new technologies, with 42%, in a recent ESET survey, aiming for better security of their finances. While this may not be quite as high as medium (80%) and large enterprises (81%), it seems that COVID-19 has acted as a catalyst, with the survey also finding that 62% of small businesses believe the pandemic has increased the need for improved security of finances.

The benefits for businesses investing in FinTech include reduction of costs, ease of use and lower barriers to entry. However, as the size of an organization naturally correlates with the budget available to spend on new technologies, here, we take a look at how different-sized enterprises have chosen to prioritize their use of FinTech solutions.

Online payments and accounting take the lead
It is perhaps no surprise that accounting functions like online payments and invoices showed the highest adoption rate for businesses of all sizes. From a list of various FinTech solutions, online payments was the most widely adopted by small (46%), medium (58%) and large (59%) businesses alike. This was closely followed by online accounting (small 41%, medium 57% and large 53%), online invoice financing and discounting (small 31%, medium 49% and large 47%), and online cashflow management (small 28%, medium 48% and large 45%).

Clearly, digital accounting has become a significant tool for small businesses, due to the benefits of streamlined systems, increased speed and productivity, and improved data security. Contrary to the notion that it is unnecessary for SMEs to digitalize due to their small scale, SMEs stand to benefit massively from adopting digital technologies to increase productivity, as well as to secure data and financial processes during recovery from the pandemic.

Big fish go for forward-thinking technologies
Where we see the medium and larger organizations storming ahead with their focus and investment is in the more forward-thinking FinTech solutions. So, while small businesses are dipping their toes in digitizing their accounting functions, medium and large businesses are further ahead in their use of branchless banks, online lending, InsurTech and RegTech.

Of these four forward-thinking technologies, InsurTech was the most adopted by medium (40%) and large (36%) businesses. According to a report by Deloitte, the pandemic shifted priorities toward increased investment in InsurTech because of the technology’s promise of “bolstering virtual customer engagement and operational efficiency.” The report states that “the amount of money invested in InsurTechs during the first half of 2020 remained remarkably robust, at nearly $2.2 billion.”

The COVID-19 pandemic has shifted the focus of all businesses, with many prioritizing plans to reduce costs, increase productivity and secure finances. FinTech solutions can offer a helping hand; it’s reassuring to see that some small businesses are benefiting as well.

For more information on how ESET can help businesses, head to our business solutions page. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Security or uninterrupted work? With Safetica 9.9 you get both.

A healthy balance between tight security and a pleasant user experience has always been Safetica’s priority. With the latest version, DLP blocking policies do not necessarily interrupt users’ work, since the admin can allow trusted users to override DLP policies and perform their desired actions without asking for help. 

Such events are recorded and can easily be audited. Thanks to users’ comments, the admin will be able to understand the context of the events much more clearly. 

User override can be configured for each policy, enabling you to control which situations and users should be allowed this flexibility. 

Control when file content scan is needed and when it is not

When your users repeatedly work with sensitive data and you know they do so in a secure way, there’s no reason why DLP should slow down their work. 

With the new Safetica version, simply create a top priority “allow” policy which describes safe operations, places, and users. Safetica will stop file scanning for such events and will allow users to work at full speed. Simple as that. 

Control data upload to non-company Git repositories

Whether you use Git for managing source code or as a document versioning system, Safetica can now help your users work with Git securely. Work with company repositories remains 100% uninterrupted, but you can easily prevent users from pushing changes and data to non-company repositories. 

Performance and security improvements

As usual, the new version comes with dozens of optimizations and bug fixes, this time focused on backend performance and faster work with records in both Safetica Management Console and WebSafetica.

Safetica Mobile users will surely welcome the increased security of our new iOS certificates. 

Announcing public beta of Safetica 9.10 with OCR!

For the first time ever, we are announcing the availability of a public beta for an upcoming version of Safetica 9.10. It will include Optical Character Recognition (OCR) and brand new content inspection technology.

OCR allows you to inspect scanned PDF documents and image files and protect them the same way as other documents. With the new content inspection technology, you also get better control over what files should be inspected and an extended list of supported file types. 

We have already tested the beta version thoroughly but want to validate its real-life performance on more variable environments. Once we are 100% certain that everything works flawlessly, we will make Safetica 9.10 available to all our customers.

Author Ján Lakatoš

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Safetica
Safetica is to provide small and mid-sized companies with the same quality data protection that corporations have – affordably, and without any additional IT administration or disruptions in operation.

Violence and Redemption: SNMP Protocol History

You know what it is, but do you know SNMP protocol history?

There was a dark time, more than dark, sepia or beige, in short, that tone in which we find the photos of our grandparents inside the drawer of the oldest and worst decorated closet in our house. A time that is hardly talked about anymore, but that points us as a weapon so that we continue to keep it in our memories. Those were the times of bank robbers and speakers, old rolls, borsalino hats and cameras with lightbulbs, they smoked more, the police were still called “coppers” and toothpaste brands had not yet produced any flavored toothpaste, not even menthol. We go back that far to get to know more about SNMP protocol history.

In this house, Pandora FMS blog, we had already talked before about the relation of the SNMP protocol with the noir part of life. It was hard, few reported that case, but we got to the media, and they, from Newcastle Tribuna to the smallest local newspaper, have endlessly asked us to come back and delve into the subject. That is why we want to make a little review of SNMP protocol history, a story full of caramel nuances and fish bones, swimming pools on the outskirts and tombs in the desert, long and slender legs and hard knuckles like the piles of prelates or pontiffs.

Naaah, in fact, if we want to find out SNMP protocol history and its evolution throughout the years, we just have to go back a couple of decades, no more. In 1988, we started having some news for the first time about this famous protocol. The 80s, pal, a very hard time too, we don’t want to take away any of its prominence. Leg heaters, carded hair and Mustangs ruled. It was around this time that what we know as the first data networks began their journey. More and more “cooler” and more and more widespread around the world.

At that time, with an administrator it was enough for an “analog” or manual way to understand a whole network infrastructure of a company. You can guess the kind of network infrastructure that could exist in a company at that time… It was made up of scarce resources or equipment because the immeasurable variety of services that are provided today did not exist, nor users, nor anything similar.

It was not until more or less the arrival of the 2000s, time of Nokias with poly tones, the return of the bell bottoms and the consolidation of Britney Spears at the highest levels of the music scene charts, that computers, Big Daddy (Internet) and the rest of the technology reached the necessary parameters to accommodate things as far ahead of their time as the SNMP protocol.

The range of services and possibilities was that expanded thanks to convergent networks that we were finally able to handle all kinds of information and data, including voice and video. Infrastructures were expanded by force, and users began to flock like flies to honey. A failure in the system could no longer be accepted. The stakes were high.

That was the time for the proliferation of monitoring systems, yes, like Pandora FMS, owner and master of this blog and my skin. They were shown as essential gadgets for the tasks of technology departments of any company that wanted to stay safe from possible incidents and even anticipate them by detecting them in advance. Monitoring systems, servers, applications, networks, events and a long list of devices. Collecting information, just what we wanted to monitor, all to collect it and represent it visually, in order to carry out the necessary actions that our systems might require. What a monitoring progress!

Like coffee, a morning shower and the geek figures in the office, it is impossible to remove monitoring systems from the daily lives of network administrators, and most of these systems are based on the Simple Network Management Protocol, also known on the streets as the SNMP Protocol, which makes the exchange of management information between network devices easier and fills our lives with hope and management data.

And this is the thick and outrageous SNMP Protocol history. in fact, it has stayed with us for many years. From that first version to SNMPv3, so focused on security and administration… And for many years more old friend! I personally hope you see my grandchildren grow old and I see you get implemented in a crass, ineluctable and ad infinitum way!

Some of the sources used for this article:

https://en.wikipedia.org/wiki/Simple_Network_Management_Protocol

https://coreun.com/2020/07/08/la-monitorizacion-protocolo-snmp-y-su-evolucio

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.